Skip to Content

MC1481309 Enhance protection of the authentication experience by blocking external script injection

Summary

  • Microsoft Entra ID sign-in pages will add stronger Content Security Policy protections to block external or injected scripts during authentication.
  • Organizations using browser extensions, monitoring tools, or customizations that inject code into the login.microsoftonline.com sign-in experience may see those tools stop working.
  • Microsoft Entra External ID tenants and MSAL/API-based authentication flows are not affected.
  • The change is enabled by default in the service update and does not require tenant configuration.
  • IT should review any sign-in page customizations, test impacted authentication flows, and replace or update unsupported tools before rollout.

Primary Service: Entra
Admin Impact: High
User Impact: Low
Release Start: 15 Oct 2026
Release End: 31 Oct 2026
Services: Entra, M365
Category: Plan for change
Tags: Admin Action, Feature Update, User Adoption

History

9/28/2026 Item Added to Message Center

Microsoft Message

As part of Microsoft’s Secure Future Initiative, we are strengthening the security of the Microsoft Entra ID sign-in experience by introducing additional Content Security Policy (CSP) protections. This change helps protect users from threats such as cross-site scripting (XSS) by allowing only trusted Microsoft-hosted scripts to run during authentication and blocking unauthorized or externally injected code.

This post is a reminder of our previous announcement (MC1191924), which communicated this upcoming security change and the actions organizations may need to take before rollout.

Rollout schedule

General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete by late October 2026

Impact on your organization

Who is affected

  • Organizations whose users authenticate through Microsoft Entra ID sign-in pages hosted on login.microsoftonline.com
  • Organizations using browser extensions, monitoring tools, customization tools, or other solutions that inject scripts into the sign-in experience
  • Microsoft Entra External ID tenants are not affected

Platforms and services

  • Microsoft Entra ID
  • Web-based authentication experiences using login.microsoftonline.com
  • Browser-based sign-in experiences across supported browsers

What will happen

  • A new Content Security Policy (CSP) header will be added to Microsoft Entra ID sign-in pages.
  • Scripts will be permitted only from trusted Microsoft content delivery network (CDN) domains.
  • Inline script execution will be restricted to trusted Microsoft-authorized sources.
  • Browser extensions and tools that inject scripts into Microsoft Entra ID sign-in pages may stop functioning.
  • Users will continue to be able to sign in even if unsupported script injection tools no longer function.
  • This change is enabled by default as part of the service update and does not require tenant configuration.
  • Microsoft Authentication Library (MSAL) and API-based authentication flows are not affected because CSP enforcement applies only to browser-based sign-in experiences using login.microsoftonline.com.

Action required and recommendations

If your organization does not use tools or extensions that inject code into Microsoft Entra ID sign-in pages, no action is required.

If your organization uses tools that inject code into the sign-in experience:

  • Review the CSP guidance and assess whether any tools, browser extensions, or custom solutions rely on script injection.
  • Test affected authentication workflows ahead of rollout.
  • Replace or update any solutions that depend on script injection into Microsoft Entra sign-in pages.
  • Communicate potential impacts to help desk and identity administration teams.
  • Update internal documentation if it references affected authentication customizations.

Learn more

  • Content Security Policy (CSP) rollout in Microsoft Entra ID – Microsoft identity platform | Microsoft Learn
  • CSP ⟶ script-src Guide
  • CSP Nonce ⟶ Script & Style Attribute
  • Enhance protection of Microsoft Entra ID authentication by blocking external script injection | Microsoft Community Hub
  • Secure Future Initiative – Secure by Design | Microsoft
  • why-xss-still-matters-msrcs-perspective-on-a-25-year-old-threat

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.